WordPress Plugin Vulnerabilities

Masteriyo LMS < 2.2.1 - Subscriber+ Privilege Escalation

Description

The plugin is vulnerable to Privilege Escalation due to an incorrect privilege assignment, making it possible for authenticated attackers with Subscriber-level access and above to elevate their privileges.

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
daroo
Verified
Yes

Timeline

Publicly Published
2026-06-08 (about 1 month ago)
Added
2026-06-18 (about 1 month ago)
Last Updated
2026-07-24 (about 1 day ago)

Other